Google Cloud just dropped an autonomous security system built to match the speed of AI-driven attacks. The new Google AI Threat Defense platform fuses Gemini models, Wiz cloud mapping, CodeMender repair agents, and Mandiant threat expertise into one always-on loop.
Attackers now weaponize AI to scan for flaws and chain exploits in minutes. Traditional human-led patching no longer keeps pace. Google responded with a four-step framework drawn from its own internal defenses: Prepare, Scan and Prioritize, Remediate, and Monitor.
Google assembled the pieces over years of acquisitions and internal builds.
Wiz, bought for $32 billion in March 2026, supplies live exposure maps across clouds, APIs, identities, and runtimes. It flags reachable assets and simulates attack paths with its Red Agent. Mandiant adds real-world incident response data and helps craft response plans for legacy systems or patch surges. Gemini and CodeMender handle deep code analysis and generate verified fixes that drop straight into developer IDEs or CLIs.
The platform prioritizes based on actual exploitability and business impact rather than raw severity scores. Multiple frontier models run in parallel because no single model catches every flaw. Lighter models scan continuously. Heavier ones focus on high-risk targets. Findings flow through Wiz context to filter noise and produce a prioritized risk map.
CodeMender then generates patches, tests them automatically, and tags libraries for full traceability. Wiz Green Agent pushes remediation across production. Mandiant guidance helps teams retire old code or roll out changes without breaking operations.
Continuous monitoring closes the loop. Autonomous agents hunt runtime anomalies. Google Security Operations integrates for detection and response. Hardened container images reduce the initial attack surface.
Francis deSouza, COO and president of security products at Google Cloud, wrote in the official announcement: “By combining the contextual risk prioritization of Wiz, the code remediation capabilities of CodeMender, the intelligence of Gemini, and the frontline expertise of Mandiant, we provide the architecture needed to match the speed of the adversary.”
Thomas Kurian, Google Cloud CEO, posted the workflow on X: Wiz scans and prioritizes risk, Gemini models scan applications, CodeMender accelerates patching, and Wiz agents keep testing for unknowns.
Industry analysts see both promise and open questions.
The Futurum Group report from May 28, 2026, noted the platform spans the full vulnerability lifecycle but raised integration risks, multicloud reach outside Google Cloud, and governance around autonomous patches. Early partners including Accenture, Deloitte, PwC, Netenrich, and TENEX.AI will handle deployments and help align with existing toolchains.
SecurityWeek covered the launch on May 28, 2026, highlighting how the system aims to shrink remediation time from weeks to minutes while organizations face machine-speed threats. The Decoder reported similar details on May 28, emphasizing the bundle of Gemini, Wiz, DeepMind’s CodeMender, and Mandiant.
Recent X posts from security watchers echo the same points: the move shifts focus from alert lists to verified repairs. One analyst noted that AI agents are now making decisions, not just supporting them.
Google built this on a decade of its own security work, from Titan chips to Zero Trust architecture and Google Security Operations. The company blocks millions of threats daily across its own infrastructure. AI Threat Defense applies that same discipline at customer scale.
Enterprises running heavy AWS or Azure workloads will watch how much of the autonomous remediation stays fully effective outside Google Cloud. Developer teams will test how CodeMender fits alongside their preferred AI coding tools. Security leaders will track audit trails for every AI-generated patch.
The launch arrives as other frontier labs push raw vulnerability discovery tools. Google’s approach owns the full stack from mapping to fix. Execution on the integrations will determine whether this becomes the default for organizations that need defense at machine speed.
Partners will play a key role in bridging organizational gaps between CIO and CISO teams. The platform touches code, cloud posture, and operations at once. Clear ownership and evidence layers for autonomous changes will matter most in production rollouts.


WebProNews is an iEntry Publication